CVE-2019-5640: Rapid7 Nexpose Information Disclosure after logout
Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the inspect element browser feature to remove the login panel and view the details available in the last webpage visited by previous user
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5640?
CVE-2019-5640 is classified as a medium severity vulnerability due to the potential for information exposure.
How do I fix CVE-2019-5640?
To fix CVE-2019-5640, upgrade Rapid7 Nexpose to version 6.6.114 or later.
What are the risks associated with CVE-2019-5640?
The risks associated with CVE-2019-5640 include unauthorized access to sensitive information if an attacker exploits the session expiration flaw.
What versions of Rapid7 Nexpose are affected by CVE-2019-5640?
CVE-2019-5640 affects all versions of Rapid7 Nexpose prior to 6.6.114.
Is there a workaround for CVE-2019-5640?
There is no official workaround for CVE-2019-5640; upgrading to the patched version is recommended.